2026 CVE Vulnerabilities

55,897 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-25405HIGH8.5Contributor SQL Injection in eRoom <= 1.7.1 versions.
CVE-2026-24639MEDIUM4.4Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.
CVE-2026-24628MEDIUM5.9Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.
CVE-2026-24552HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'All...
CVE-2026-24537MEDIUM4.3Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.
CVE-2026-64611HIGH7.5A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing ...
CVE-2026-16745HIGH8.8A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network b...
CVE-2026-65758HIGH8.2Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submission...
CVE-2026-65757HIGH8.1Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - T...
CVE-2026-65756MEDIUM6.1Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitr...
CVE-2026-65755HIGH7.5Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extensio...
CVE-2026-65754HIGH7.5Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths c...
CVE-2026-65713MEDIUM6.5Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumera...
CVE-2026-65712MEDIUM6.2Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check...
CVE-2026-65431CRITICAL9.8Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extr...
CVE-2026-65430HIGH7.5Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in...
CVE-2026-64876HIGH8.8Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-up...
CVE-2026-64875MEDIUM6.5Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups trusted spoofable forw...
CVE-2026-64874CRITICAL9.8Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed i...
CVE-2026-64873CRITICAL9.8Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or re...
CVE-2026-64872MEDIUM6.5Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could es...
CVE-2026-64871MEDIUM5.4Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Admi...
CVE-2026-64799HIGH7.5Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions ...
CVE-2026-16078MEDIUM6.5The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all ...
CVE-2026-15906MEDIUM6.5The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now